Executive Summary
| Summary | |
|---|---|
| Title | Vulnerability in Windows Kernel |
| Informations | |||
|---|---|---|---|
| Name | MS11-087 | First vendor Publication | 2011-12-13 |
| Vendor | Microsoft | Last vendor Modification | 2011-12-13 |
| Severity (Vendor) | Critical | Revision | 1.0 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Severity Rating: Critical Revision Note: V1.0 (December 13, 2011): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted document or visits a malicious Web page that embeds TrueType font files. |
Original Source
| Url : http://technet.microsoft.com/en-us/security/bulletin/MS11-087 |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:15645 | |||
| Oval ID: | oval:org.mitre.oval:def:15645 | ||
| Title: | TrueType Font Parsing Vulnerability (CVE-2011-3402) | ||
| Description: | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2011-3402 |
Version: | 9 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 |
Product(s): | Microsoft Silverlight 4 Microsoft Silverlight 5 Microsoft Office 2003 Microsoft Office 2007 Microsoft Office 2010 |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:15290 | |||
| Oval ID: | oval:org.mitre.oval:def:15290 | ||
| Title: | TrueType Font Parsing Vulnerability (CVE-2011-3402) | ||
| Description: | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2011-3402 |
Version: | 3 |
| Platform(s): | Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows XP |
Product(s): | Microsoft Lync 2010 Microsoft Lync 2010 Attendee |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:13998 | |||
| Oval ID: | oval:org.mitre.oval:def:13998 | ||
| Title: | Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege | ||
| Description: | Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability." | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2011-3402 |
Version: | 7 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Os | 2 | |
| Os | 3 | |
| Os | 5 | |
| Os | 2 | |
| Os | 2 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 76843 | Microsoft Windows Win32k TrueType Font Handling Privilege Escalation |
Metasploit Database
| id | Description |
|---|---|
| No date | Windows Gather Forensics Duqu Registry Check |

MS11-087
(Critical)
(High)







